Re: [Full-disclosure] TLS / SSLv3 vulnerability explained (New ways to leverage the vulnerability)

2009-12-11 Thread Thierry Zoller
BID 36935 ERRATA: The previous trace POC was renamed to 36935-3.c on securityfocus and had a small error in it. It is now fixed and available here. I'd like to ask repositories to update. File available here: http://www.g-sec.lu/ssl-trace-poc.c Original Paper:

[Full-disclosure] TLS / SSLv3 vulnerability explained (New ways to leverage the vulnerability)

2009-11-30 Thread Thierry Zoller
Dear List, I updated the whitepaper with a lot of new information, some leveraging the vulnerability in other ways that certainly increase the effectiveness and impact of this vulnerability. A brief warning to those that think they are safe because they don't accept